A high-severity vulnerability, CVE-2026-54061, affects Dgraph Alpha versions earlier than 25.3.5 and allows unauthenticated attackers to reach external snapshot import RPCs exposed on the public gRPC port 9080. The flaw is an authentication bypass (CWE-306) in which a remote client can send Badger stream data to a target group store without authentication or authorization, enabling direct tampering with database contents over the network.
Because the receiving process calls Prepare() before processing the imported stream, successful exploitation can delete and replace existing database data, creating high integrity and availability risk. The issue carries a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, and the CVE record indicates proof-of-concept and automatable exploitation with total technical impact. Dgraph addressed the issue in version 25.3.5, which organizations should treat as the fixed release for exposed Alpha deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-54061 was updated with references and SSVC information indicating proof-of-concept exploitation, automatable exploitation, and total technical impact. The issue describes unauthenticated external snapshot import in Dgraph Alpha that can delete and replace group store data.
Dgraph published version 25.3.5, the release identified in the CVE record as the version that fixes the authentication bypass issue affecting earlier releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.